Datatilsynet (Denmark) · 27 November 2023
The Central Denmark Region
About: Data principles, Special categories, Unlawful processing
FineNo fineViolation found
- Regulator
- Datatilsynet (Denmark)
- Decided
- 27 November 2023
- Country
- Denmark
- Sector
- Not given
- Regulator’s reference
- 2023-432-0016
- Fino case number
- 2023/DK/013
What happened
Examining the publication by a hospital of patients' data on Instagram, the Danish DPA found a violation of Article 6(1)(a) and Article 9(2)(a) GDPR. The DPA stated that the processing could not be based on consent since, due to the power asymmetries between patients and the hospital, patients could not have given their consent freely.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 4Definitions4(11)Read →
- Art. 5Principles relating to processing of personal data5(1)Read →
- Art. 6Lawfulness of processing6(1)(a)Read →
- Art. 9Processing of special categories of personal data9(2)(a)Read →
- Data principles
- Special categories
- Unlawful processing
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2023/DK/013.